• v7.9.0
    • v7.11.0 (latest)
    • v7.10.0
    • v7.9.0
    • v7.8.0
    • v7.7.0
    • v7.6.0
    • v7.5.0
    • v7.3.0
    • v7.2.0
    • v7.1.1
    • v7.1.0
    • v7.0.8
  • Services & Support
  • Devo.com
  • Contact
    • Contact Us
    • Request a Demo
    • Partner Inquiry
  • Log In
    • USA Devo
    • EU Devo
PREVIOUS
Scenario 1: Apply a fixed tag to all events
NEXT
Scenario 3: Filter out unwanted events

Sending data to Devo / Devo Relay / Configuring Devo Relay / Configuring Devo Relay from the web application / Relay input configuration / 5 common relay rule scenarios / Scenario 2: Apply a Devo tag based on data found in the inbound event

Download as PDF

Scenario 2: Apply a Devo tag based on data found in the inbound event

Another straight-forward scenario involves assigning a fixed Devo tag based upon data contained in any part of the source event. For example, if the tag in the event's syslog header is ABC, then apply the Devo tag one.two.three. Based on where the data is contained in the source event, you can use the Source tag, Source message, or Source data field.

Create the rule

  1. Identify the port on which the relay will receive the inbound events. It is good practice to dedicate a single port to a single event source when possible.
  2. Describe the specific values to look for in the Source tag, Source message, or Source data fields. For a detailed description of these fields, see Defining a relay rule.
  3. Enter the Devo tag in the Target tag field.
  4. (optional) Select the Stop processing checkbox to prevent any further rules from processing the event if the current rule was successful. If the current rule is unsuccessful, processing will continue.

Take for example...

The rule for processing log events sent from the pfsense firewall fits this scenario. When the syslog tag of events received on port 514 is pf, then the rule applies the Devo tag firewall.pfsense.firewall.  Because Stop processing is selected, the event will not be subjected to further rules if this rule is successful. 

To learn about the fields in the relay rule form, check out the Defining a relay rule article.


Related articles

  • firewall.pfsense
  • Defining a relay rule
Download as PDF

PREVIOUS
Scenario 1: Apply a fixed tag to all events
NEXT
Scenario 3: Filter out unwanted events

Export

See what Devo can do for you. Request a demo!
Discover what's new (Release notes)
  • v7.9.0
    • v7.11.0 (latest)
    • v7.10.0
    • v7.9.0
    • v7.8.0
    • v7.7.0
    • v7.6.0
    • v7.5.0
    • v7.3.0
    • v7.2.0
    • v7.1.1
    • v7.1.0
    • v7.0.8
  • Services & Support
  • Devo.com
  • Contact
    • Contact Us
    • Request a Demo
    • Partner Inquiry
  • Log In
    • USA Devo
    • EU Devo
  • +1 888 6830910 (USA)
  • +34 900 838 880 (Spain)
Copyright © 2019 Legal Terms Privacy Policy Cookies Policy

Powered by Confluence and Scroll Viewport